Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-4032

24
FAUCET Score

CVE-2024-4032 describes a vulnerability in Python's "ipaddress" module where the is_private and is_global properties incorrectly identified certain IPv4 and IPv6 addresses, failing to align with current IANA Special-Purpose Address Registries. This issue affects Python versions prior to CPython 3.12.4 and 3.13.0a6. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and no user interaction required, potentially leading to high confidentiality impact. However, there is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.10.0, < 3.10.15CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.10CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.12.0, < 3.12.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 0, < 3.8.20CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.9.0, < 3.9.20CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.07%
Probability of exploitation in next 30 days
EPSS Percentile
61.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0107 is in the 38th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.9.19-6
microsoftpatch availablevia msrc
Product: 17303-16823Fixed in: 3.9.19-6
microsoftpatch availablevia msrc
Product: 19681-17086Fixed in: 3.9.19-6
microsoftpatch availablevia msrc
Product: 17604-17084Fixed in: 3.12.9-1
microsoftpatch availablevia msrc
Product: 17545-17084Fixed in: 3.12.9-1
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-6 on CBL Mariner 2.0Fixed in: 3.9.19-6
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-13 on CBL Mariner 2.0Fixed in: 3.9.19-6
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-1 on Azure Linux 3.0Fixed in: 3.12.9-1
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.3-5 on Azure Linux 3.0Fixed in: 3.12.9-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.9.19-6
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8100020240826142629.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8100020240826142629.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12-0:3.12.5-2.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11-0:3.11.9-7.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-67.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: python3-0:3.6.8-47.el8_6.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: python3-0:3.6.8-47.el8_6.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: python3-0:3.6.8-47.el8_6.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: python3-0:3.6.8-51.el8_8.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9-0:3.9.18-3.el9_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11-0:3.11.7-1.el9_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12-0:3.12.5-2.el9
View patch

Vendor Advisories (5)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
microsoft2024-Oct/CVE-2024-4032

CVE-2024-4032

Oct 8, 2024
redhatCVE-2024-4032Low

python: incorrect IPv4 and IPv6 private ranges

Jun 17, 2024
microsoft2024-Jun/CVE-2024-4032Important

Incorrect IPv4 and IPv6 private ranges

Jun 11, 2024

References

lists.debian.org / debian-lts-announce/2024/12/msg00000.html
github.com / python/cpython/commit/22adf29da8d99933ffed8647d3e0726edd16f7f8
github.com / python/cpython/commit/40d75c2b7f5c67e254d0a025e0f2e2c7ada7f69f
github.com / python/cpython/commit/895f7e2ac23eff4743143beef0f0c5ac71ea27d3
github.com / python/cpython/commit/ba431579efdcbaed7a96f2ac4ea0775879a332fb
github.com / python/cpython/commit/c62c9e518b784fe44432a3f4fc265fb95b651906
github.com / python/cpython/commit/f86b17ac511e68192ba71f27e752321a3252cee3
github.com / python/cpython/issues/113171
github.com / python/cpython/pull/113179
mail.python.org / archives/list/[email protected]/thread/NRUHDUS2IV2USIZM2CVMSFL6SCKU3RZA
security.netapp.com / advisory/ntap-20240726-0004
iana.org / assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml
iana.org / assignments/iana-ipv6-special-registry/iana-ipv6-special-registry.xhtml
openwall.com / lists/oss-security/2024/06/17/3